Hacking Hardware Picofly - a HWFLY switch modchip

HackMan37

Active Member
Newcomer
Joined
May 26, 2023
Messages
37
Trophies
0
XP
78
Country
Dominican Republic
About the emmc corruption, @abal1000x seems the most knowledgeable in emmc stuff (sorry if I'm wrong, haven't been active here for long).
Even with dat0/1 short shouldn't hekate boot? I have the bad adapter, is it even worth it to remove it and cut the lobe from the dat1 side like you suggest if I have constant sucessful glitch? I can mount GPP, not sure if there's any way to verify if there's boot0/1 corruption using ums-loader.
Btw I'm using @floxcap version of ums-loader that has some changes to the code to test emmc and it says my mmc is ok.

Is there any way to test DRAM? Any way to just confirm that it is the problem?

@floxcap did you ever made the changes to ums-loader to test DRAM read/write?
@HackMan37 any luck modding ums-loader?

Thanks in advance!
For me, no success, i was trying to modify the hekate, but just get the "basic" version "working", but have the screen "bugged", so just "works" to reboot into rcm, or try to boot without checking the fusses, that can be made with a modded version of ums-loader
 
  • Like
Reactions: roxzii

rehius

Well-Known Member
Member
Joined
Feb 6, 2023
Messages
377
Trophies
1
Age
34
XP
1,790
Country
Canada
Thx, but whats the purpose?
Required to properly wake up the NS from sleep. When you use emuNAND, CPU fuses might become desynced with your bootloader. This file contains all the information to boot the CPU.
When you update the original system, it is necessary to update this file by booting to OFW using hekate menu (not the "Reboot/OFW" but the another one, "More Configs" -> "Full Stock" in some famous sets)
 

abal1000x

Well-Known Member
Member
Joined
Jun 5, 2022
Messages
1,070
Trophies
0
XP
1,395
Country
Gaza Strip
Thx, but whats the purpose?
Not too sure.

You might open new thread, or goes to hekate thread or github issue, and asking them for the purposes.

I read the code slightly (not seriously read), its about checking the fuse count, if the fuse count incorrect, the sleep wont work. So its kind of patching that, so the sleep still working.
I might wrong, you need to ask in their issue, to be sure.
 
  • Like
Reactions: QuiTim and [Truth]

[Truth]

Well-Known Member
Member
Joined
Mar 21, 2006
Messages
1,057
Trophies
1
Location
Mushroom Kingdom
XP
2,383
Country
Germany
Required to properly wake up the NS from sleep. When you use emuNAND, CPU fuses might become desynced with your bootloader. This file contains all the information to boot the CPU.
When you update the original system, it is necessary to update this file by booting to OFW using hekate menu (not the "Reboot/OFW" but the another one, "More Configs" -> "Full Stock" in some famous sets)
Thanks!

You mean via
fss0=atmosphere/package3 stock=1 emummc_force_disable=1
in hekate config?
 

CarlosCruz

Member
Newcomer
Joined
Jul 11, 2023
Messages
24
Trophies
0
Age
35
XP
129
Country
Spain
One mosfet oled 👍
 

Attachments

  • Screenshot_20230713-212925.png
    Screenshot_20230713-212925.png
    3.1 MB · Views: 52
  • 20230713_210223.mp4
    29.3 MB

FXDX

Well-Known Member
Member
Joined
Sep 15, 2019
Messages
325
Trophies
0
XP
2,001
Country
Dominican Republic
Picofly soldered on Oled with mosfet on the back pcb. I took the mosfet from the defective connection ribbon of one Hwfly. I used some thin copper wire to solder on the capacitor and loaded it with more tin. Excellent glitch time.
 

Attachments

  • 1.jpeg
    1.jpeg
    200.3 KB · Views: 57
  • 2.png
    2.png
    7.2 MB · Views: 44
  • 3.png
    3.png
    6.2 MB · Views: 54
  • 4.png
    4.png
    6.4 MB · Views: 52
  • 5.png
    5.png
    6.9 MB · Views: 50
  • 6.png
    6.png
    6.9 MB · Views: 47
  • 39D3FE8F-18BF-4975-9DF1-40BC28763496.jpeg
    39D3FE8F-18BF-4975-9DF1-40BC28763496.jpeg
    1.8 MB · Views: 48
  • 85276701-4828-4570-B041-0629AAD15B38.jpeg
    85276701-4828-4570-B041-0629AAD15B38.jpeg
    2.9 MB · Views: 44
  • B99A628D-1EE2-4E01-BD24-E727FD269683.jpeg
    B99A628D-1EE2-4E01-BD24-E727FD269683.jpeg
    3.1 MB · Views: 42
  • C4E26972-B35A-435C-828A-95D7290C64FC.jpeg
    C4E26972-B35A-435C-828A-95D7290C64FC.jpeg
    2.8 MB · Views: 44
  • E7A799DA-B6E8-4362-8A0E-F690BF9C9644.jpeg
    E7A799DA-B6E8-4362-8A0E-F690BF9C9644.jpeg
    2.1 MB · Views: 46
  • F7C9062C-EF09-4D28-986C-2FD844A181DC.jpeg
    F7C9062C-EF09-4D28-986C-2FD844A181DC.jpeg
    2.5 MB · Views: 42
  • 65F6AC96-D9AB-44EE-899D-B066D6EE4DBB.jpeg
    65F6AC96-D9AB-44EE-899D-B066D6EE4DBB.jpeg
    2.5 MB · Views: 37
  • hjjjhhj.jpg
    hjjjhhj.jpg
    155 KB · Views: 31
  • ytytytyt.jpg
    ytytytyt.jpg
    151.9 KB · Views: 43
Last edited by FXDX,

revsgrow

Member
Newcomer
Joined
Jul 13, 2023
Messages
14
Trophies
0
Age
27
Website
www.instagram.com
XP
52
Country
Brazil
Hi, good evening,
I'm new here in forum and i need your help.

I bought a very cheap Switch V2, when i was unlocking, I realized that it already had passed in other hands. :sad:
The Caps and Pads of the positive points SP1 and SP2 on the APU was removed.
Is there a way of recover these Pads or any other alternative points to unlock it???

Looking this topic I saw it's possible to install MOSFET on the OLED's back. Can i install it on V2?
Thanks for your attention.

See the images bellow.
 

Attachments

  • photo_5010613473373170674_y.jpg
    photo_5010613473373170674_y.jpg
    162.7 KB · Views: 48
  • photo_5010613473373170675_y.jpg
    photo_5010613473373170675_y.jpg
    164 KB · Views: 49
Last edited by revsgrow,

lightninjay

Well-Known Member
Member
Joined
Mar 28, 2023
Messages
560
Trophies
0
Age
31
XP
1,385
Country
United States
Hi, good evening,
I'm new here in forum and i need your help.

I bought a very cheap Switch V2, when i was unlocking, I realized that it already had passed in other hands. :sad:
The Caps and Pads of the positive points SP1 and SP2 on the APU was removed.
Is there a way of recover these Pads or any other alternative points to unlock it???

Looking this topic I saw it's possible to install MOSFET on the OLED's back. Can i install it on V2?
Thanks for your attention.

See the images bellow.
 

FreeLander

Well-Known Member
Member
Joined
Apr 6, 2023
Messages
350
Trophies
0
Age
35
XP
467
Country
United States
Picofly soldered on Oled with mosfet on the back pcb. I took the mosfet from the defective connection ribbon of one Hwfly. I used some thin copper wire to solder on the capacitor and loaded it with more tin. Excellent glitch time.
Nice work. What's your glitch time?
 

abal1000x

Well-Known Member
Member
Joined
Jun 5, 2022
Messages
1,070
Trophies
0
XP
1,395
Country
Gaza Strip
Excuse me, but doing what was indicated I was not successful.

Am I using a different firmware than the one indicated for this installation?

I'm using firmware 2.73.

Thanks!!
In summary, majority problem is the installation.

Show us the video of the error light.
Some picture of the works, the mosfet, dat0, clk, cmd, reset, rp2040 board, so we could help to confirm it.
 
  • Like
Reactions: QuiTim and revsgrow

revsgrow

Member
Newcomer
Joined
Jul 13, 2023
Messages
14
Trophies
0
Age
27
Website
www.instagram.com
XP
52
Country
Brazil
In summary, majority problem is the installation.

Show us the video of the error light.
Some picture of the works, the mosfet, dat0, clk, cmd, reset, rp2040 board, so we could help to confirm it.
the error code shown when starting the switch is ==* (two long pulses and one short pulse)

According to the error code, I mean this is not mosfet!

but I redid the installation twice and was unsuccessful.

Remembering that my APU does not have SP2 or SP2 points.
So I'm looking for alternative points to solder the mosfet and pull the GATE to the picofly.

Tomorrow I will send the pictures.

Thanks.
 

revsgrow

Member
Newcomer
Joined
Jul 13, 2023
Messages
14
Trophies
0
Age
27
Website
www.instagram.com
XP
52
Country
Brazil
In summary, majority problem is the installation.

Show us the video of the error light.
Some picture of the works, the mosfet, dat0, clk, cmd, reset, rp2040 board, so we could help to confirm it.
I was checking the installation scheme image and realized where I could be going wrong.

I realized that from the Source to the Gate of the mosfet IR8242 there is a capacitor/resistor (I couldn't identify) that I didn't put in my installation.

Could you tell me what component this is, what is its value and where can I find it?

thanks!
 
  • Like
Reactions: FXDX

abal1000x

Well-Known Member
Member
Joined
Jun 5, 2022
Messages
1,070
Trophies
0
XP
1,395
Country
Gaza Strip
I was checking the installation scheme image and realized where I could be going wrong.

I realized that from the Source to the Gate of the mosfet IR8242 there is a capacitor/resistor (I couldn't identify) that I didn't put in my installation.

Could you tell me what component this is, what is its value and where can I find it?

thanks!
I don't quite understand with your meaning.

If you mean the pulldown resistor, its not mandatory.
The glitch will work without the pulldown resistor.
 
  • Like
Reactions: FXDX and revsgrow

revsgrow

Member
Newcomer
Joined
Jul 13, 2023
Messages
14
Trophies
0
Age
27
Website
www.instagram.com
XP
52
Country
Brazil
Picofly soldered on Oled with mosfet on the back pcb. I took the mosfet from the defective connection ribbon of one Hwfly. I used some thin copper wire to solder on the capacitor and loaded it with more tin. Excellent glitch time.
I don't quite understand with your meaning.

If you mean the pulldown resistor, its not mandatory.
The glitch will work without the pulldown resistor.
I realize that my installation is not the same as this one.
Because this is missing a component that is connected from the source to the gate of the mosfet.

I would like to know what component this is, along with the value so that I can put it in my installation.

remembering that I'm not using the NP2040 mosfet, I'm using the IR8242.
 
  • Like
Reactions: FXDX

abal1000x

Well-Known Member
Member
Joined
Jun 5, 2022
Messages
1,070
Trophies
0
XP
1,395
Country
Gaza Strip
I realize that my installation is not the same as this one.
Because this is missing a component that is connected from the source to the gate of the mosfet.

I would like to know what component this is, along with the value so that I can put it in my installation.

remembering that I'm not using the NP2040 mosfet, I'm using the IR8242.
That is pull down resistor, its not mandatory.
Without it the glitching still works.

Take a photo on your works, if there are probable mistakes we might point it out.
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
    Xdqwerty @ Xdqwerty: Nvm i didnt "hear", it's a truth +1